STIGQter STIGQter: STIG Summary: Mirantis Kubernetes Engine Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

Allowing users and administrators to schedule containers on all nodes must be disabled.

DISA Rule

SV-260917r966108_rule

Vulnerability Number

V-260917

Group Title

SRG-APP-000141-CTR-000315

Rule Version

CNTR-MK-000490

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set MKE and MSR to disallow administrators and users to schedule containers.

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Orchestration. Scroll to down "Container Scheduling".

Disable the "Allow administrators to deploy containers on MKE managers or nodes running MSR".

Disable "Allow users to schedule on all nodes, including MKE managers and MSR nodes" options.

Click "Save".

Check Contents

To ensure this setting has not been modified follow these steps on each node:

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Orchestration. Scroll to down "Container Scheduling".

Verify that the "Allow administrators to deploy containers on MKE managers or nodes running MSR" is disabled. If it is checked (enabled), this is a finding.

Verify that the "Allow users to schedule on all nodes, including MKE managers and MSR nodes" is disabled. If it is checked (enabled), this is a finding.

Vulnerability Number

V-260917

Documentable

False

Rule Version

CNTR-MK-000490

Severity Override Guidance

To ensure this setting has not been modified follow these steps on each node:

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Orchestration. Scroll to down "Container Scheduling".

Verify that the "Allow administrators to deploy containers on MKE managers or nodes running MSR" is disabled. If it is checked (enabled), this is a finding.

Verify that the "Allow users to schedule on all nodes, including MKE managers and MSR nodes" is disabled. If it is checked (enabled), this is a finding.

Check Content Reference

M

Target Key

5595